The DPDK vhost-user interface does not check to verify that all the requested guest physical range is mapped and contiguous when performing Guest Physical Addresses to Host Virtual Addresses translations. This may lead to a malicious guest exposing vhost-user backend process memory. All versions before 18.02.1 are vulnerable.
CVSS Details
- CVSS 3.1 Base Score: 6.1
- CVSS 3.0 Vector: (CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:C/C:H/I:N/A:N)
Covered by Rapid7
| Product | Vendor Advisory | Solution File | Added | Published |
|---|---|---|---|---|
| Centos_linux | — | Upgrade openvswitch-ovn-hostUpgrade python-openvswitchUpgrade openvswitch-testUpgrade dpdkUpgrade openvswitch-ovn-vtepUpgrade openvswitch-ovn-commonUpgrade openvswitch-debuginfoUpgrade dpdk-toolsUpgrade dpdk-debuginfoUpgrade dpdk-docUpgrade openvswitch-ovn-centralUpgrade openvswitchUpgrade openvswitch-develUpgrade dpdk-devel | Aug 28, 2019 | Apr 24, 2018 |
| Debian | — | Upgrade dpdk | Jul 30, 2024 | Apr 24, 2018 |
| Redhat_linux | — | Upgrade openvswitch-ovn-hostUpgrade dpdk-develUpgrade dpdk-debuginfoUpgrade python-openvswitchUpgrade openvswitchUpgrade openvswitch-ovn-centralUpgrade openvswitch-testUpgrade openvswitch-develUpgrade openvswitch-ovn-vtepUpgrade dpdk-toolsUpgrade dpdkNo solution existsUpgrade openvswitch-ovn-commonUpgrade dpdk-docUpgrade openvswitch-debuginfo | May 1, 2018 | Apr 24, 2018 |
| Suse | — | Upgrade libdpdk-17_11Upgrade dpdk-thunderx-develUpgrade dpdk-develUpgrade dpdkUpgrade libdpdk-20_0Upgrade dpdk-toolsUpgrade dpdk-thunderxUpgrade dpdk-kmp-defaultUpgrade libdpdk-18_11Upgrade libdpdk-17_11-0Upgrade dpdk-thunderx-kmp-default | Jun 4, 2018 | Apr 24, 2018 |
| Ubuntu | — | Upgrade dpdk | May 17, 2018 | Apr 24, 2018 |
Prioritise with Active Threat Intelligence
With curated Threat Intelligence, you can see which vulnerabilities truly put you at risk, prioritize what matters most, and act before attackers do.
Explore Intelligence Hub